Description
In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role.
Remediation
References
http://www.securityfocus.com/bid/94221
https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger
Related Vulnerabilities
CVE-2020-15256 Vulnerability in npm package object-path-set
CVE-2014-10065 Vulnerability in npm package remarkable
CVE-2023-28155 Vulnerability in maven package org.webjars.bower:request
CVE-2017-5929 Vulnerability in maven package ch.qos.logback:logback-core
CVE-2020-2149 Vulnerability in maven package org.jenkins-ci.plugins:repository-connector